Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but omits it from the database query. A project member can use an issue_id they control in the URL while targeting another user's attachment by its pk UUID. Because the server matches only pk, workspace, and project_id, it modifies the attachment regardless of the issue_id in the URL. When the attachment is pending and has not been confirmed as uploaded, the PATCH handler sets created_by = request.user and transfers attachment ownership to the attacker. This issue is fixed in 1.4.0. | |
| Title | Plane: Issue Attachment Ownership Hijacking via Missing `issue_id` Scope | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T18:22:11.592Z
Reserved: 2026-10-05T16:40:39.611Z
Link: CVE-2026-105633
Updated: 2026-10-05T18:22:00.957Z
Status : Deferred
Published: 2026-10-05T18:17:36.757
Modified: 2026-10-05T19:17:17.213
Link: CVE-2026-105633
No data.
OpenCVE Enrichment
No data.